Privacy Policy
Last updated 30 July 2026
Groundlore (“we”, “us”) is a coffee-cup-reading service for delight and entertainment. This policy explains, plainly, what we collect and what we do with it. We do not sell your data, we do not show advertising, and we keep collection to the minimum the service needs.
What we collect
- Your Google account basics. When you sign in with Google we receive your name, email address, and profile picture. We use these only to identify your account and keep your readings with you across devices.
- Your cup photos. When you request a reading, the photo you take or upload is sent to our server and on to our AI provider to generate the reading. We do not store your photos — the image is processed to produce the reading and then discarded. Only the resulting reading text is kept.
- Your readings. The text of each reading (greeting, symbols, message) and the optional name, theme, and question you provide are stored so you can revisit your history.
- Basic technical data. Standard server logs (e.g. IP address and request time) used to keep the service secure and prevent abuse.
- How the site is used. Which pages are viewed and which buy links are clicked, measured with Google Analytics 4. We run it with storage consent denied by default — so it is not permitted to write analytics cookies or similar identifiers to your device unless that ever changes and we ask you first — and with IP anonymisation on. It tells us how many people read a page. It is not used for advertising and we do not run ads.
- If you tap “Keep & share”. That publishes part of the reading at a
groundlore.com/r/…link, and anyone who has that link can open it without signing in. The public page shows the symbols the cup held and what they meant, the message and the closing. It deliberately leaves out the greeting (which carries the name you gave), your question and the cup’s answer. Share pages are excluded from search engines. If you want one taken down, email us and we will remove it. The parts left out of the public page can be unlocked, for that one reading only, by whoever redeems the $29 printed edition against that link — a licence is tied to the first reading it opens and cannot open any other.
Why we are allowed to
- To give you what you asked for — your account, your reading, your history, and anything you bought. In GDPR terms this is performance of our contract with you.
- To keep the service standing up — server logs, rate limits and anti-abuse measures. This is our legitimate interest in not being knocked over or defrauded.
- To count page views — analytics, run in the restricted, no-device-storage mode described above. If we ever want to switch on cookie-based analytics or advertising measurement, we will ask your consent first, and until you give it that switch stays off.
How long we keep it
- Your cup photo: not kept at all. It is used to write the reading and discarded.
- Your readings and account: kept until you ask us to delete them, so your history is still there when you come back. To be straight with you: there is no automatic expiry today — nothing deletes an old account on a timer. One email removes everything attached to your account. A reading you took before signing in has no account and no email on it, so we cannot find it from your address — if you want one of those removed, send us its share link (groundlore.com/r/…) and we will delete it.
- Server logs: 14 days, then they are rotated away.
- Analytics: aggregate page-view counts held by Google under its own retention settings. It does not contain your photo, your reading or your name.
Where your data lives
Your account and readings are stored on our own server, hosted in the European Union (Frankfurt, Germany). Your sign-in session is held in a secure, encrypted cookie on your own device.
Sending your photo abroad
The reading itself is written by Anthropic, which is in the United States, so at the moment of the reading your cup photo and the inputs you typed leave the EU. That transfer is covered by Anthropic’s data processing agreement, which incorporates the European Commission’s Standard Contractual Clauses — the standard legal mechanism for this. You can read Anthropic’s terms at anthropic.com/legal/commercial-terms. Nothing else about you is sent outside the EU except the anonymised analytics events described above.
Who we share with
We use a small number of trusted providers to run the service, and only for that purpose:
- Anthropic (the AI that writes your reading) — receives your cup photo and reading inputs at the moment of the reading. Anthropic does not use this data to train its models on by default for API traffic.
- Google — provides sign-in. We never receive your Google password.
- Google Analytics — receives anonymised page-view and buy-link-click events. It does not receive your photo, your reading, your question or your name. Page addresses are sent with identifiers stripped: the query string is never included, and the id in a
/r/…or/keepsake/…address is replaced with a placeholder before the event is sent, so neither a share link nor a purchase licence key reaches Google. - Gumroad — only if you buy the $9 guide or the $29 printed edition. Gumroad is the seller of record and takes the payment, so it holds your purchase details. We never see your card details. See our Terms.
We do not sell or rent your personal data to anyone, and we do not share it for advertising.
Your rights
You can ask us to: show you the data we hold about you, correct it, delete it, send you a copy of it, or stop a particular use of it. One email is enough — write to hello@groundlore.com and we will act on it. You never have to give a reason and it never costs anything.
If you are in the EU or the UK and you think we have handled your data badly, you can also complain to your national data protection authority — you do not have to come to us first, though we would rather you did so we can fix it.
Your choices
- You can sign out at any time from within the app.
- You can ask us to delete your account and all stored readings — email us and we will remove them.
- You can ask us to take down a
groundlore.com/r/…share page you created.
Children
Groundlore is intended for adults (18+) and is not directed at children.
Changes
If this policy changes, we will update the date above and post the new version here.
Who is responsible for your data
The data controller is Sam Arora (Arora Enterprises, a sole proprietorship), trading as Groundlore. Groundlore was previously called ReadMyCup; you may still see that name on older files. There is no separate data protection officer — questions and requests go to Sam Arora directly at hello@groundlore.com, and we aim to acknowledge within 48 hours and resolve within one month.
Contact
Questions or deletion requests: hello@groundlore.com.